0% found this document useful (0 votes)
3 views6 pages

Stealing Personal Data On Android

Methods of Stealing Personal Data on Android Using a Remote Administration Tool With Social Engineering Techniques

Uploaded by

Fatra 88
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views6 pages

Stealing Personal Data On Android

Methods of Stealing Personal Data on Android Using a Remote Administration Tool With Social Engineering Techniques

Uploaded by

Fatra 88
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ISSN 2085-4552

Methods of Stealing Personal Data on Android


Using a Remote Administration Tool with
Social Engineering Techniques
Ridwan Satrio Hadikusuma1, Lukas2, Epril M Rizaludin3
1 ,2
Electrical Engineering Master Departement, Universitas Katolik Indonesia Atma Jaya, Jakarta, Indonesia
3
PT. Klik Digital Sinergi, Jakarta, Indonesia
1
ridwan.202200090017@[Link], 2lukas@[Link], 3epril_mohamadrizaludin@[Link]

Accepted 24 March 2023


Approved 28 June 2023

Abstract— IT security is a significant concern of the still be penetrated if the user is still easy to manipulate,
internet because almost all communication occurs today. especially using social engineering methods. Social
The purpose of testing personal data theft with the social engineering is a manipulation technique that exploits
engineering method is to ensure that the system and human error to access private information or valuable
network on the user's Android have security holes to be
hacked if the user is not aware of social engineering that
data [7-9]. In the world of cybercrime, this type of
allows data theft through the remote administration tool human hacking scam can lure unsuspecting users. The
(RAT) which is accidentally downloaded on the Android most common is manipulating Android users to install
User. Installing a RAT by applying social engineering is an application (possibly under the guise of an e-ticket,
the possible and proper way to steal Android user privacy package delivery receipt numbers for tracking, to other
data. This study outlines some basic concepts of data deceptive applications), where these applications are
theft, from recent call data and personal data to remote administration tools used for personal data theft
controlling Android users' cameras and microphones [10][11]. Remote addressing tools android hacking is a
remotely. technology that allows someone to remotely access an
Index Terms— RAT; security; social engineering. Android device without having to be near the device.
Hackers use remote addressing tools to exploit
I. INTRODUCTION vulnerabilities or loopholes in the Android security
system to access the device and gain access to sensitive
One of the most significant inventions in human data such as photos, text messages, or financial
history that have changed how we do things is the information [12, 13].
Internet. The Internet has changed how we
communicate, do business, and interact with each Hackers use remote addressing tools (RAT) for
other[1-2]. Today, people no longer have to wait to hear malicious purposes such as data theft, extortion, or
from someone because they can communicate easily other criminal activities. However, this technology can
through the Internet. The Internet has also enabled also be used positively, for example, to help Android
businesses and individuals to receive payments device owners who have forgotten their passwords or
instantly and track their fleets and cargo [3]. Security pins or to monitor people who need help, such as
and information technology are increasingly important children or the elderly [14]. It is important to remember
to society and the ICT(Information and Communication that using remote addressing tools for unethical
Technology) industry in this modern era. Security purposes can compromise the privacy and security of
experts have developed various high-performance one's Android device. Therefore, keeping your Android
security tools to ensure that information on the Internet device safe is essential by installing the latest security
remains safe and not vulnerable to attack [4]. Various apps, updating the operating system regularly, and
techniques, such as Layered Design, Assurance or avoiding downloading apps from sources you do not
Proof of Correctness, Software Engineering trust. This article will discuss some of the most
Environment, and Penetration Testing, test a complete, frequently used remote addressing tools in Android
integrated, and reliable software, hardware, and people hacking and how to protect your Android device from
operational computer base[5, 6]. these threats.

One example is using open-source frameworks such II. METHODOLOGY


as Metasploit for exploit creation and penetration
testing, which comes with over 1,600 exploits and 495 Before the authors conduct research, the authors
payloads to attack computer networks and systems. No conduct several literature studies from several related
matter how strong an android's security system is, it can studies that are still relevant to the research to be
conducted. one of them is research conducted by
44 Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023
ISSN 2085-4552

Huang, Y., & Han, X. [15] in his research entilted successfully retrieved from the Android device.
"Security Analysis of Remote Administration Tools for Furthermore, researchers will evaluate the results of the
Android Devices". In this study, the researchers tests and analyses carried out and provide
analyzed the security of six popular remote recommendations regarding actions that need to be
administration tools for Android devices, and found taken to improve the security of Android devices from
that these tools are vulnerable to social engineering attacks using remote administration tools and social
attacks. this is also in line with research conducted by engineering. Briefly, the flow of this research is
Iliyasu, A. M., & Ahmad, M. O [16] in his research described in Figure 1 below.
related to "A Comprehensive Study on Android Remote
Administration Tools: Threats, Vulnerabilities and
Countermeasures". In this study, the researchers
conducted a comprehensive analysis of Android remote
administration tools, and identified various threats and
vulnerabilities associated with these tools. The
researchers also proposed a set of countermeasures to
mitigate these risks.
Different from what Prakash, S., & Jadhav, S [17]
did in an article entitled "Social Engineering Attacks in
Android Platform. 2018 International Conference on
Intelligent Computing and Control Systems (ICICCS)".
In this study, the researchers analyzed the various social
engineering attacks that can be used to exploit
vulnerabilities in Android devices, and proposed a set
of countermeasures to prevent such attacks. there is
another study entitled "A Study on Remote
Administration Tools and Their Impact on Android
Devices" conducted by Ravikumar, N., & Gokulnath, C
[18]. In this study, the researchers analyzed the impact
of remote administration tools on Android devices, and Fig. 1. Research Flowchart
identified various security risks associated with these
tools. The researchers also proposed a set of A. Determination of Remote Administration Tools
countermeasures to mitigate these risks. Finally, what Installing remote administration tools on the Kali
is interesting for the author's research in conducting this Linux operating system can be done by downloading
research is in research entitled "A Review on Security the installation package according to the operating
Threats and Countermeasures for Android Remote system and architecture used. After that, the installation
Administration Tools" conducted by Singh, G., & package can be installed on Kali Linux using the
Kapoor, S [19]. In this study, the researchers conducted appropriate installation commands. However,
a review of the security threats associated with Android remember that using remote administration tools in
remote administration tools, and proposed a set of hacking activities is illegal and can violate privacy and
countermeasures to prevent these threats. The harm others. Therefore, remote administration tools
researchers also discussed the importance of user must be used with good ethics and pay attention to
education in preventing social engineering attacks. security and privacy aspects. In addition, using Kali
Linux must be done for good and legal purposes, such
III. RESEARCH METHOD as conducting security tests on a system or network
The research method on remote administration tools owned or with permission from the owner of the system
Android hacking using social engineering can be done or network.
in several stages. First, researchers must select and
Determining remote administration tools for
identify the types of remote administration tools used
Android hacking can be done by looking for references
on Android devices. Then, the researcher must identify
from various sources, such as underground forums,
the security vulnerabilities in each remote
websites, or blogs about information security, or using
administration tool. After that, researchers must
a unique search engine such as Shodan. Then, it is
conduct trials of each remote administration tool by
necessary to evaluate the tools found in terms of
carrying out attacks by exploiting the security holes
functionality, capability, security, and the legality of
found. In this case, researchers will use social
their use. Data collection methods related to Android
engineering techniques to trick Android device users so
hacking remote administration tools can be done using
that they can install remote administration tools
scanning and enumeration techniques on the target
unknowingly. After successfully installing the remote
system or network. This can be done using special tools
administration tools on the Android device, researchers
like Nmap, hoping, or the Metasploit framework. In
will conduct testing and analysis of the data
Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023 45
ISSN 2085-4552

addition, using tools such as Wireshark can also assist antivirus applications to identify and block malicious
in collecting data related to network traffic that occurs applications. Suppose you suspect that RATs or other
when using remote administration tools on the target. malicious applications have infected your Android
device. In that case, the first step is to remove the
B. Social Engineering Techniques application from the device and perform a system scan
Social engineering methods of installing RAT using an antivirus. Also, it is recommended to
applications can be carried out in various ways, such as continuously update the Android operating system to
creating fake messages or emails that look genuine, the latest version and avoid using unprotected or
creating websites or pages that mimic the appearance of untrusted Wi-Fi networks. By paying attention to these
official sites, or using other tactics that trick the target security measures, Android users can minimize the risk
into downloading and installing applications that of attacks by RATs and other malicious applications
contain malware. These techniques usually involve and protect their privacy and personal data.
psychological manipulation of the target, such as
TABLE I. ACCEPTANCE LEVEL CATEGORY INTERVAL
making fraudulent offers or promises, intimidating or
threatening, exploiting curiosity, and taking advantage Percentage Interval Acceptance Level
of the target's trust or ignorance. It is important to Category
0% - 20% Strongly Disagree
remember that these actions are illegal and may harm
20.01% - 40% Disagree
others. Therefore, it is crucial for technology users 40.01% - 60% Uncertain
always to be vigilant and careful when obtaining 60.01% - 80% Agree
information or downloading applications from 80.01% - 100% Strongly Agree
unknown sources. In addition, it is also essential to
IV. RESULTS AND DISCUSSION
update the device security system and use the latest
security software to avoid harmful malware attacks. A. Operating System Installation and Remote
Administration Tools Identification Results
C. Methods of Data Collection and Prevention
Kali Linux is a distribution specifically designed for
Collecting personal data using hacking remote penetration testing, including in android hacking. Kali
administration tools (RAT) on Android devices can be Linux has several advantages in its use that make it
done in various ways. One common way is sending easier for practitioners to do hacking. One of the
malicious applications embedded with RATs to the advantages of Kali Linux is that it is equipped with a
target device. Once the application is installed on the variety of complete hacking tools. Hence, users no
target device, RATs can collect personal data such as longer need to install additional tools manually. Apart
text messages, phone calls, and browsing history. In from that, Kali Linux also has an intuitive user interface
addition, RATs can also be used to take control of the so that users can efficiently operate the system and the
target device, such as activating the camera or tools provided. Another advantage is modifying and
microphone and recording user activity without their customizing the tools according to user needs through
knowledge. Another method is to use phishing manual configuration or built-in features such as meta-
techniques, such as sending fake messages or emails packages. Thus, Kali Linux is one of the right choices
that trick users into providing their personal for android hacking practitioners in conducting security
information or clicking on links containing malicious testing on the Android system. Here are the Kali Linux
applications embedded in RATs. In addition, users can installation steps [11]:
also become victims of RATs attacks through
1. Download the Kali Linux ISO file from the
unprotected Wi-Fi networks or applications that are
official Kali Linux website.
vulnerable to attack, such as banking or e-commerce
applications [7]. 2. Prepare an empty USB flash drive with a
minimum capacity of 4 GB.
Therefore, it is essential for Android users always to 3. Download and install the Rufus application to
be careful and avoid downloading apps from untrusted create a bootable USB. Open the Rufus
sources and using protected and trusted Wi-Fi application and select the USB flash drive to
networks. In addition, users are also advised to use use.
security applications to monitor and protect their
4. In the "Boot selection" section, click the
devices from RATs and other malware attacks.
"SELECT" button and select the Kali Linux
Android's fairly tight security system protects its users
ISO file downloaded in step 1.
from remote administration tools (RAT) attacks and
other malicious applications. One way to increase 5. Ensure the USB flash drive partition is in
Android security is to activate security features "MBR" mode, and the file system is "FAT32".
provided by the operating system, such as a password 6. Click the "START" button and wait until the
or PIN, fingerprint sensor, or screen pattern lock bootable USB creation process is complete.
settings [20]. In addition, users are also advised not to
download applications from untrusted sources or use

46 Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023


ISSN 2085-4552

7. After the process, insert the USB flash drive applicable regulations. As for AhMyth's appearance as
into the computer where Kali Linux will be shown in Figure 2 below.
installed.
8. Set the BIOS settings to boot from the USB
flash drive the first time. The method depends
on the type and brand of your computer or
laptop.
9. Select the "Graphical Install" option on the Kali
Linux boot menu after successfully booting
from the USB flash drive.
10. Follow the on-screen installation instructions,
including selecting the language, time zone,
and hard drive partition to use. Fig. 2. Display the AhMyth RAT and run the server command
11. Select the root password setting and create a
new user account. B. Results of Social Engineering
12. Wait for the installation process to finish. Once After the RAT is deployed into an application, the
done, Kali Linux is ready to use. next step is manipulating the target to install the RAT
Installing Kali Linux requires basic knowledge of application on their Android device. Various ways can
the operating system and BIOS settings. Therefore, be done, such as sending e-tickets and package delivery
ensure you understand the instructions and the receipts to government assistance programs, as shown
associated risks before starting the installation process. in Figure 3 below.
Another alternative in Linux installation is to use a
virtual machine (virtual server) to run the operating
system.
After the operating system is installed, the next step
is to determine the RAT that will be used. the author
uses AhMyth as a RAT which will be used to commit
personal data theft. AhMyth is a popular Android
hacking tool and relatively easy to use on Kali Linux.
Here are the steps to run AhMyth on Kali Linux [18]:
1. First, ensure that Kali Linux is installed and
updated with the latest version.
2. Then, open the terminal on Kali Linux and run
the command "git clone
[Link]
[Link]" to download the AhMyth source code
from GitHub.
3. After successfully downloading, enter the
AhMyth directory with the command "cd
AhMyth-Android-RAT".
4. Next, run the command "sudo sh [Link]"
to start the AhMyth installation process on Kali
Linux. Fig. 3. Social Engineering Results
5. Wait for the installation process to finish, and
after that, open AhMyth by typing the When doing social engineering to get someone to
command "sudo sh ahmyth". install Remote Administration Tools (RAT) on an
6. After AhMyth opens, users can start creating an Android device, it takes some persuasive skills to
Android application that will be injected with convince the victim. First, an aggressor needs to know
the AhMyth payload. To do so, users can about the victim's interests and wants. Furthermore, the
follow the instructions available on AhMyth. attacker can create a scenario to interest the victim and
7. Once done, AhMyth is ready to hack the target make him interested in installing the RAT application.
Android device. One trick often used is to promise an attractive offer,
such as a free application or a premium service at a low
However, remember that unauthorized use of cost. Attackers can also use phishing techniques by
AhMyth on devices not belonging to the user is illegal sending fake emails or text messages that look genuine
and can result in serious legal consequences. Therefore, and offer an attractive application or service. In
AhMyth must be used ethically and comply with addition, attackers can also take advantage of the
Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023 47
ISSN 2085-4552

victim's fear or worry about the security of Android


devices.
Attackers can promise better device security by
installing a RAT application when in fact, the
application is dangerous malware. To ensure success in
getting someone to install the RAT application, the
attacker needs to master effective and creative
persuasive techniques and constantly update and
improve these techniques so that they can always trick
the victim. However, it is essential to remember that
such actions are illegal and can cause harmful effects
on others and, therefore, should not be carried out.
Fig. 6. The author view currently controlling the target android
C. Results of Personal Data Theft device's camera

After the RAT is installed on the target device, the


author can find the country, device type, and IP used, as
shown in Figure 4. Since the first installation, all user
data on the Android device can be accessed and fully
controlled by the author (also in this research, the target
is part of the author and already with permission).

Fig. 7. Author display in monitoring the real-time location of the


Fig. 4. Device information from the attacker side
target device

The first data result is that the author steals or takes Finally, the author can access all storage files from
contact data stored on the target android device (see the target android device as a whole, starting from photo
figure 5). the contact data can be used for various and external storage files to the android system files
things, such as being sold to online gambling sites for themselves (see fig. 8). Of course, this crucial data can
marketing needs, fraud, and many other digital crimes. be used for various digital crimes, the most dangerous
of which is hacking an M-Banking account installed on
a user's device.

Fig. 5. Contact information is stored on the target device

The author also managed to hack the camera, Fig. 8. Monitoring of target android device folder from author side
microphone and real-time location of the target android
device, which can be controlled 24 hours a day, as
shown in Figure 6 and Figure 7.

48 Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023


ISSN 2085-4552

V. CONCLUSION [7] B. Al-Duwairi, "A Study on Security Issues of Mobile Devices


and Applications", International Journal of Advanced
Based on the research that has been done, the use of Computer Science and Applications, vol. 8, no. 9, pp. 239-244,
social engineering techniques in installing Remote 2017.
Administration Tools on Android devices is very [8] S. Arora, A. Singh, "Mobile Malware Detection: A Review",
effective. In this study, researchers convinced International Journal of Advanced Research in Computer
Science and Software Engineering, vol. 7, no. 5, pp. 76-79,
respondents to install applications containing Remote 2017.
Administration Tools by making convincing fake [9] A. Babar, M. Masood, M. Farooq, "An Analysis of Mobile
messages or phone calls. In addition, the research Malware: A Comprehensive Study", International Journal of
results also show that security on the Android system is Computer Science and Network Security, vol. 15, no. 3, pp.
still very vulnerable to Remote Administration Tools 103-112, 2015.
attacks that can take over the device remotely and [10] S. Bhattacharya, S. Kumar, "A Study on Android Malware
Detection and Prevention Techniques", International Journal of
collect users' data without their knowledge. Computer Applications, vol. 168, no. 5, pp. 8-12, 2017.
Therefore, it is necessary to take better precautions [11] K. Chandrakar, S. Bhoi, "Mobile Security: Issues, Challenges
and Future Directions", International Journal of Advanced
and safeguards on Android devices to prevent malicious
Research in Computer Science, vol. 8, no. 3, pp. 118-123,
Remote Administration Tools attacks. Some steps to 2017.
avoid these attacks include downloading apps only [12] A. Dhiman, S. Sharma, "Security Issues and Solutions for
from trusted sources, keeping your Android device Mobile Devices", International Journal of Computer
updated with the latest security patches, and installing Applications, vol. 104, no. 12, pp. 21-26, 2014.
reliable antivirus software. Additionally, awareness and [13] N. M. N. Lestari and A. W. Nugroho, "Penerapan Teknik
education are also needed for Android users to Social Engineering dalam Remote Administration Tools pada
Android," Jurnal Keamanan Informasi, vol. 5, no. 1, pp. 12-21,
recognize and prevent Remote Administration Tools 2021.
attacks that use social engineering techniques. [14] D. F. Maulana, R. A. Hidayat, and R. D. Saputra, "Analisis
Penggunaan Remote Administration Tool dengan Teknik
REFERENCES Social Engineering pada Android," Jurnal Ilmiah Informatika,
vol. 10, no. 2, pp. 123-130, 2019.
[1] A. R. Maulana and D. P. Wardhana, "Remote Administration [15] Huang, Y., & Han, X. (2018). Security Analysis of Remote
Tool (RAT) Implementation using AhMyth and Social Administration Tools for Android Devices. 2018 IEEE
Engineering Techniques," 2020 International Conference on International Conference on Cloud Computing and Big Data
Computer Engineering, Network and Intelligent Multimedia Analysis (ICCCBDA).
(CENIM), Surakarta, Indonesia, 2020, pp. 1-5, doi:
10.1109/CENIM51083.2020.9317252. [16] Iliyasu, A. M., & Ahmad, M. O. (2021). A Comprehensive
Study on Android Remote Administration Tools: Threats,
[2] W. R. Pratama and A. F. T. Riyadi, "Uji Penetrasi Remote Vulnerabilities and Countermeasures. Journal of Information
Administration Tool pada Android dengan Teknik Social Security, 12(2), 79-97.
Engineering," Jurnal Teknologi Informasi dan Komunikasi,
vol. 8, no. 2, pp. 56-62, 2022. [17] Prakash, S., & Jadhav, S. (2018). Social Engineering Attacks
in Android Platform. 2018 International Conference on
[3] R. H. Putra, M. N. Huda and T. A. Wisesa, "Android Hacking Intelligent Computing and Control Systems (ICICCS).
Using AhMyth RAT with Social Engineering Techniques,"
2020 4th International Conference on Informatics and [18] Ravikumar, N., & Gokulnath, C. (2016). A Study on Remote
Computing (ICIC), Jakarta, Indonesia, 2020, pp. 1-5, doi: Administration Tools and Their Impact on Android Devices.
10.1109/IAC50653.2020.9259369. International Journal of Advanced Research in Computer
Science and Software Engineering, 6(8), 262-268.
[4] S. Pradana, D. D. Setiawan and N. E. Darmawan, "Remote
Administration Tool (RAT) Implementation using AhMyth [19] Singh, G., & Kapoor, S. (2018). A Review on Security Threats
RAT and Social Engineering Techniques," 2021 International and Countermeasures for Android Remote Administration
Conference on Advanced Informatics: Concept, Theory and Tools. International Journal of Advanced Engineering
Application (ICAICTA), Malang, Indonesia, 2021, pp. 1-6, Research and Science, 5(11), 122-126.
doi: 10.1109/ICAICTA51487.2021.9488906. [20] N. Hidayatullah, I. A. Akbar, and R. Kurniawan, "Social
[5] S. R. S. Maharjan, S. Maharjan and S. Adhikari, "Social Engineering-Based Attack on Android Mobile Device," in
Engineering Techniques and the Use of Remote Access 2019 International Conference on Information Management
Trojans (RATs) in Android Devices," 2019 4th International and Technology (ICIMTech), 2019, pp. 82-87.
Conference on Computing, Communication and Security
(ICCCS), Rome, Italy, 2019, pp. 1-6, doi:
10.1109/CCCS.2019.8887181.
[6] R. Agarwal, S. Saha, S. Chaki, "Security Issues and Threats in
Android Platforms: A Survey", International Journal of
Computer Applications, vol. 52, no. 6, pp. 28-35, 2012.

Ultimatics : Jurnal Teknik Informatika, Vol. 15, No. 1 | June 2023 49

You might also like